git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2] http.c: don't rewrite the user:passwd string multiple times

From
BCBrandon Casey <bcasey@nvidia.com>
Date
Jun 19, 2013, 02:43 UTC
Message-ID
<1371609829-31813-1-git-send-email-bcasey@nvidia.com>
In-Reply-To
<CA+sFfMcsOx14UdzLF_JsgkpUQU6yG7DE+00eA3d+Lo-qncDgew@mail.gmail.com>
From: Brandon Casey <drafnel@gmail.com>

Curl older than 7.17 (RHEL 4.X provides 7.12 and RHEL 5.X provides 7.15) requires that we manage any strings that we pass to it as pointers. So, we really shouldn't be modifying this strbuf after we have passed it to curl.

Our interaction with curl is currently safe (before or after this patch) since the pointer that is passed to curl is never invalidated; it is repeatedly rewritten with the same sequence of characters but the strbuf functions never need to allocate a larger string, so the same memory buffer is reused.

This "guarantee" of safety is somewhat subtle and could be overlooked by someone who may want to add a more complex handling of the username and password. So, let's stop modifying this strbuf after we have passed it to curl, but also leave a note to describe the assumptions that have been made about username/password lifetime and to draw attention to the code.

Signed-off-by: Brandon Casey <drafnel@gmail.com>
---
 http.c | 12 +++++++++---
 1 file changed, 9 insertions(+), 3 deletions(-)
diff --git a/http.c b/http.c
index 92aba59..2d086ae 100644
--- a/http.c
+++ b/http.c
@@ -228,9 +228,15 @@ static void init_curl_http_auth(CURL *result)
 #else
 	{
 		static struct strbuf up = STRBUF_INIT;
-		strbuf_reset(&up);
-		strbuf_addf(&up, "%s:%s",
-			    http_auth.username, http_auth.password);
+		/*
+		 * Note that we assume we only ever have a single set of
+		 * credentials in a given program run, so we do not have
+		 * to worry about updating this buffer, only setting its
+		 * initial value.
+		 */
+		if (!up.len)
+			strbuf_addf(&up, "%s:%s",
+				http_auth.username, http_auth.password);
 		curl_easy_setopt(result, CURLOPT_USERPWD, up.buf);
 	}
 #endif
-- 
1.8.3.1.440.gc2bf105
Previous: Brandon CaseyNext: Jeff King
Message 9 of 11 in “http.c: don't rewrite the user:passwd string multiple times”
  1. http.c: don't rewrite the user:passwd string multiple timesBrandon Casey, Jun 18, 2013
  2. Eric SunshineJun 18, 2013
  3. Jeff KingJun 18, 2013
  4. Daniel StenbergJun 18, 2013
  5. Junio C HamanoJun 18, 2013
  6. Brandon CaseyJun 18, 2013
  7. Jeff KingJun 18, 2013
  8. Brandon CaseyJun 19, 2013
  9. http.c: don't rewrite the user:passwd string multiple timesBrandon Casey, Jun 19, 2013
  10. Jeff KingJun 19, 2013
  11. Daniel StenbergJun 19, 2013

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.